Skip to content

ci(cd): build multi-arch images (amd64 + arm64) - #64

Merged
torridfish merged 1 commit into
mainfrom
ci/multi-arch-images
Sep 14, 2026
Merged

torridfish merged 1 commit into
mainfrom
ci/multi-arch-images

Conversation

@torridfish

@torridfish torridfish commented Jul 16, 2026 •

Copy link
Copy Markdown
Member

目的

Publish arm64 images alongside amd64 so the service runs natively on the arm64 (Oracle Ampere) deploy host. Images are amd64-only today.

方法/實作說明

Add linux/arm64 to the build-push platforms in the CD workflow. QEMU and Buildx are already configured, so the published tags (:stable / :dev / semver / sha-*) become multi-arch manifest lists.

  • 主要修改:
    • .github/workflows/cd.yml
  • 關鍵實作:
    • Multi-platform buildx build via docker/build-push-action (provenance / sbom unchanged).

關聯 Issue

Closes #65.

附註

  • arm64 builds run under QEMU (fugashi build + UniDic download), so CD will be noticeably slower.
  • This PR currently blocks the api-tools half of continuous deployment in jpcorrect-backend#47.

@torridfish
torridfish marked this pull request as draft July 16, 2026 08:51
torridfish added a commit that referenced this pull request Jul 16, 2026
Build the image on PRs (no push) so a broken Dockerfile — the
pyopenjtalk compile and the open_jtalk_dic / UniDic bake layers that
make the runtime self-contained — fails the PR instead of the release
build. A --network none smoke test runs the in-process OpenJTalk
frontend to confirm the baked dictionaries resolve offline.

amd64 only; arm64 PR gating is left to the multi-arch work in #64.
torridfish added a commit that referenced this pull request Jul 16, 2026
Build the image on PRs (no push) so a broken Dockerfile — the
pyopenjtalk compile and the open_jtalk_dic / UniDic bake layers that
make the runtime self-contained — fails the PR instead of the release
build. A --network none smoke test runs the in-process OpenJTalk
frontend to confirm the baked dictionaries resolve offline.

amd64 only; arm64 PR gating is left to the multi-arch work in #64.
@sessatakuma sessatakuma deleted a comment from chatgpt-codex-connector Bot Jul 24, 2026
@torridfish
torridfish changed the base branch from main to feat/commercializable-openjtalk September 13, 2026 12:27
torridfish added a commit to sessatakuma/jpcorrect-backend that referenced this pull request Sep 13, 2026
#38 added runtime hardening to the backend service in compose.deploy.yml
(read_only + tmpfs /tmp + no-new-privileges). This stack replaces that file,
so re-apply it and extend it to everything the stack runs:

- backend-dev gets the same three keys as backend-prod. Dev skips the app-level
  auth middlewares, so the container-level guarantees matter more there.
- api-tools-prod / api-tools-dev get them too. Verified on the arm64 deploy
  host: a read-only api-tools container serves /docs and a real MarkAccent
  request, so the bundled OpenJTalk/UniDic dicts need nothing writable but /tmp.
- postgres-{prod,dev} keep a writable rootfs (initdb + PGDATA) but get
  no-new-privileges; verified the entrypoint's drop to the postgres user still
  works under it.
- cloudflared gets no-new-privileges, and both watchtowers get the full set.
- cloudflared and watchtower are pinned to explicit versions instead of :latest.
  Watchtower holds the Docker socket, which makes it the last thing that should
  float; 1.7.1 is verified working on the deploy host.

Also turn auto-update off for api-tools only. Watchtower stays scope-split per
env, but both api-tools services now carry watchtower.enable=false: the backend
publishes multi-arch images since #38, while API-tools is still amd64-only, so a
pull on the arm64 host would replace a working image with an unrunnable one.
Blocked on sessatakuma/API-tools#64; the runbook documents how to flip it back.

Finally, keep publishing :latest alongside :dev on the default branch so the
conventional tag can't silently go stale.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
torridfish added a commit to sessatakuma/jpcorrect-backend that referenced this pull request Sep 13, 2026
#38 added runtime hardening to the backend service in compose.deploy.yml
(read_only + tmpfs /tmp + no-new-privileges). This stack replaces that file,
so re-apply it and extend it to everything the stack runs:

- backend-dev gets the same three keys as backend-prod. Dev skips the app-level
  auth middlewares, so the container-level guarantees matter more there.
- api-tools-prod / api-tools-dev get them too. Verified on the arm64 deploy
  host: a read-only api-tools container serves /docs and a real MarkAccent
  request, so the bundled OpenJTalk/UniDic dicts need nothing writable but /tmp.
- postgres-{prod,dev} keep a writable rootfs (initdb + PGDATA) but get
  no-new-privileges; verified the entrypoint's drop to the postgres user still
  works under it.
- cloudflared gets no-new-privileges, and both watchtowers get the full set.
- cloudflared and watchtower are pinned to explicit versions instead of :latest.
  Watchtower holds the Docker socket, which makes it the last thing that should
  float; 1.7.1 is verified working on the deploy host.

Also turn auto-update off for api-tools only. Watchtower stays scope-split per
env, but both api-tools services now carry watchtower.enable=false: the backend
publishes multi-arch images since #38, while API-tools is still amd64-only, so a
pull on the arm64 host would replace a working image with an unrunnable one.
Blocked on sessatakuma/API-tools#64; the runbook documents how to flip it back.

Finally, keep publishing :latest alongside :dev on the default branch so the
conventional tag can't silently go stale.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@torridfish
torridfish added this pull request to stack #66 September 13, 2026 12:44
Base automatically changed from feat/commercializable-openjtalk to main September 13, 2026 14:50
@github-actions

Copy link
Copy Markdown

🛡️ PR Quality Check Summary

✅ PR Title: Passed (Length: 47/75, Format: OK). ci(cd): build multi-arch images (amd64 + arm64)
✅ Branch Name: Follows naming convention (ci/multi-arch-images)
✅ Commit Messages: All 1 commit(s) passed (Length, Format, Case)
✅ Conflicts: No merge conflict markers found
✅ Python Quality: All checks passed.


🎉 All checks passed!

@torridfish
torridfish marked this pull request as ready for review September 13, 2026 14:54
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-13T14:56:47.030483Z f028216 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

amd64-only images cannot run on the arm64 (OCI Ampere) deploy host

2 participants